The exploit targeting Coldcard hardware wallets has intensified significantly, with cumulative losses now approaching $89 million across thousands of compromised addresses. Galaxy Research reports that attackers have launched a third wave of systematic thefts, draining approximately 1,367 BTC from 4,585 distinct addresses since the vulnerability became widely known Decrypt.

Coinkite, the manufacturer behind the Coldcard devices, issued an emergency security alert on July 30 warning that specific firmware versions contained a critical software error in the wallet generation process CryptoSlate. This flaw enabled attackers to access and drain funds from affected wallets, with the exploitation continuing across multiple waves as users fail to update vulnerable devices or move funds to secure locations.

The financial impact has reverberated beyond individual losses, distorting broader Bitcoin market signals. The massive movement of funds—characterized by analysts as the largest Bitcoin migration since the FTX collapse—has rendered on-chain analytics temporarily unreliable CryptoSlate. Security researchers and blockchain analysts now struggle to differentiate between organic market activity and the forced redistribution of assets as victims and white-hat responders attempt to secure remaining funds from compromised addresses.

The incident has also highlighted systemic vulnerabilities in contemporary cybersecurity infrastructure. Specifically, the exploit has exposed recurring weaknesses in AI-assisted cyber defense systems, which proved insufficient to detect or prevent the automated draining operations affecting thousands of wallets CryptoSlate. This failure raises questions about the reliability of machine learning-based threat detection when confronting novel firmware-level vulnerabilities in hardware security devices.

The scale of the compromise has created unprecedented challenges for blockchain surveillance firms attempting to track the flow of stolen assets. The distributed nature of the 4,585 affected addresses complicates efforts to blacklist or monitor attacker-controlled destinations, while the sheer volume of transactions has temporarily congested network analysis tools typically used to detect anomalous behavior.

With losses mounting through successive waves of attacks, the situation underscores the critical importance of firmware verification and immediate migration protocols for hardware wallet users. The ongoing nature of the third wave suggests that attackers maintain active access to vulnerable address sets, continuing automated exploitation as users delay updating or replacing affected Coldcard devices.